Description
A security flaw has been discovered in poco-ai poco-agent up to 0.5.4. Affected is the function WorkspaceManager._setup_session_persistence of the file executor/app/core/workspace.py of the component Claude File Handler. The manipulation results in incomplete cleanup. The attack may be performed from remote. Attacks of this nature are highly complex. The exploitability is told to be difficult. The exploit has been released to the public and may be used for attacks.
Published: 2026-08-06
Score: 6.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The WorkspaceManager._setup_session_persistence function in poco-agent's Claude File Handler contains a flaw that allows an attacker to manipulate the persistence setup so that the cleanup routine does not fully remove session data. Because the attack can be carried out remotely, an adversary could persist malicious state or leftovers, potentially exposing residual data or enabling repeated abuse of the session environment. The flaw is described as highly complex and difficult to exploit, yet public proof‑of‑concepts have already been released.

Affected Systems

poco-ai's poco-agent component, versions up to 0.5.4, is affected. Any deployment of poco-agent 0.5.4 or earlier that includes the Claude File Handler in its workspace management path is vulnerable.

Risk and Exploitability

The CVSS base score of 6.3 indicates a medium severity vulnerability. No EPSS score is available, and the issue is not listed in CISA KEV. The exploit was disclosed publicly and can be triggered remotely, but the required manipulation is sophisticated, making real‑world exploitation challenging. However, because the flaw results in incomplete cleanup, the risk remains significant if attackers achieve the initial manipulation step.

Generated by OpenCVE AI on August 6, 2026 at 09:26 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade poco-agent to a version newer than 0.5.4 that contains the proper cleanup logic for WorkspaceManager._setup_session_persistence.
  • If an upgrade is not possible, impose strict authorization controls on any input that influences session persistence configuration to prevent unauthorized manipulation.
  • Monitor session cleanup logs and audit for anomalous persistence behavior that might indicate an attempted exploitation.

Generated by OpenCVE AI on August 6, 2026 at 09:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 06 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 06 Aug 2026 08:15:00 +0000

Type Values Removed Values Added
Description A security flaw has been discovered in poco-ai poco-agent up to 0.5.4. Affected is the function WorkspaceManager._setup_session_persistence of the file executor/app/core/workspace.py of the component Claude File Handler. The manipulation results in incomplete cleanup. The attack may be performed from remote. Attacks of this nature are highly complex. The exploitability is told to be difficult. The exploit has been released to the public and may be used for attacks.
Title poco-ai poco-agent Claude File workspace.py WorkspaceManager._setup_session_persistence cleanup
First Time appeared Poco-ai
Poco-ai poco-agent
Weaknesses CWE-459
CPEs cpe:2.3:a:poco-ai:poco-agent:*:*:*:*:*:*:*:*
Vendors & Products Poco-ai
Poco-ai poco-agent
References
Metrics cvssV2_0

{'score': 4, 'vector': 'AV:N/AC:H/Au:N/C:N/I:P/A:P/E:POC/RL:ND/RC:C'}

cvssV3_0

{'score': 4.8, 'vector': 'CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 4.8, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 6.3, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Poco-ai Poco-agent
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-08-06T14:58:31.682Z

Reserved: 2026-08-05T21:28:55.397Z

Link: CVE-2026-19019

cve-icon Vulnrichment

Updated: 2026-08-06T14:58:27.436Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-06T12:00:06Z

Weaknesses